SC-100 Practice Question: Design solutions that align with security best practices and priorities
A company is deploying Microsoft Entra ID Governance. They need to implement a least privilege access model for their Azure resources. Which TWO features should they use? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse Identity Protection (a risk-detection tool) or Conditional Access (an access-enforcement tool) with governance features that directly manage role assignments and time-bound access, leading candidates to overlook the two specific features designed for least privilege in Azure resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management (PIM)
Privileged Identity Management (PIM) is correct because it provides just-in-time (JIT) privileged access to Azure resources, enabling time-bound and approval-based role activation. This directly supports a least privilege model by ensuring users only have elevated permissions when needed, reducing standing access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privileged Identity Management (PIM)
Why this is correct
PIM provides just-in-time, time-bound, and approval-based activation of privileged roles across Microsoft Entra ID, Azure resources, and other Microsoft services. It eliminates permanent standing admin access by requiring users to request activation for a limited window, with MFA and policy-based approvals. In an Entra ID governance deployment, PIM directly governs the assignment and activation of privileged roles, making it the correct answer for the scenario.
- ✗
Identity Protection
Why it's wrong here
Identity Protection is a risk detection service that uses machine learning to identify compromised identities and suspicious sign-ins, such as impossible travel or leaked credentials. It does not manage resource access assignments or create approval workflows for access; instead, it feeds risk signals into Conditional Access to gate sign-ins. Therefore, it is not an access governance mechanism for deploying Entra ID governance.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access is a policy engine that evaluates signals like user risk, location, and device health at authentication time to allow or block sign-in sessions. It enforces the conditions under which access occurs but does not grant, modify, or expire permissions to resources, nor does it handle access requests or approvals. Consequently, it is not responsible for governing the lifecycle of resource access.
- ✗
Microsoft Intune compliance policies
Why it's wrong here
Intune compliance policies define device security standards, such as required OS versions, encryption settings, and threat levels, and mark devices as compliant or non-compliant. They integrate with Conditional Access to restrict access from non-compliant devices, but they have no function in assigning or revoking user permissions to applications or groups. Thus, they are not relevant to Entra ID access governance.
- ✓
Entitlement Management
Why this is correct
Entitlement Management enables the creation of access packages that bundle a set of resources—such as groups, applications, and SharePoint sites—with policies governing who can request access, who must approve, and how long access lasts. It automates assignment and removal, supports separation-of-duties checks, and can provide access to external users. This is a core capability of Entra ID governance, so it is a correct answer in this context.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.